MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c3947877937f742316d50176a391987c78cc0ce88c7bbb34230c17f169b63f29. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c3947877937f742316d50176a391987c78cc0ce88c7bbb34230c17f169b63f29
SHA3-384 hash: b8355057579714edd717aedcdeba230509fa0317853f8fe1436594a3cf5a90b11e5ee05fff194dbabe8b7adee09769c2
SHA1 hash: 78cd8f70089f91f33cc7d4225c71c6f4c2b88954
MD5 hash: db1aa5bbd61f515583db8cf60e544d27
humanhash: twenty-illinois-cola-ack
File name:IMG_6512345987652345678.arj
Download: download sample
Signature AveMariaRAT
File size:122'214 bytes
First seen:2020-09-07 15:05:59 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 3072:mf8hMohMbZm4IpRIPhVnUfDoOuC8+yezEEKd5evXv:mfYEZxI7kUvJ8C/Kd5iv
TLSH 4DC312DF549E218E3B77D039AAA8B14565A837A92CC0446F44D0C18639AB24FDD3FCBC
Reporter GovCERT_CH
Tags:AveMariaRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Spyware.AveMaria
Status:
Malicious
First seen:
2020-09-07 15:07:05 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

arj c3947877937f742316d50176a391987c78cc0ce88c7bbb34230c17f169b63f29

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments